The Dutch Ministry of Finance disclosed that attackers gained unauthorized access to internal systems supporting several primary processes within its policy department. The breach was detected after a third-party notification, and the ministry later blocked access to affected systems while an investigation continued, leaving some employees unable to log in and disrupting internal operations.
The ministry has not said which systems were compromised, how long the intruders had access, how many staff were affected, or whether any sensitive data was stolen. Officials said public-facing services remained operational, including systems used by the Tax Administration, Customs, and the Benefits service for tax collection, import and export processing, and income-linked subsidies, and no threat actor has publicly claimed responsibility.

See the actors and campaigns active against you right now.
4 events from the most recent confirmed update back to the earliest known activity.
By 2026-03-31, the Dutch Ministry of Finance had taken multiple systems offline, including its treasury banking portal, disrupting online treasury services for roughly 1,600 public institutions. The outage blocked functions such as balance viewing, loans, deposits, credit requests, intraday limit changes, and report generation, though funds remained accessible through regular banking channels.
On 2026-03-23, the ministry publicly confirmed the cyber incident and said public-facing services run by the Tax Administration, Customs, and Benefits were not affected. Officials did not disclose which specific systems were impacted, how long access lasted, or whether data was stolen.
After reviewing the incident, the ministry blocked access to compromised systems to contain the breach while an investigation continued. The disruption prevented some employees from logging in and affected internal operations.
On 2026-03-19, the Dutch Ministry of Finance detected unauthorized access to some internal systems after receiving a notification from a third party. The affected systems supported several primary processes within the ministry's policy department.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
7 references tracked. Mallory keeps watching after this page renders.
bleepingcomputer.com
Open sourcesecurityaffairs.com
Open sourcetherecord.media
Open sourcebleepingcomputer.com
Open sourcenos.nl
Open sourcerijksoverheid.nl
Open sourceismg-cdn.nyc3.cdn.digitaloceanspaces.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.